Protocol Reference

Documentation, flow diagrams, and security considerations for each protocol family.

An identity layer built on top of OAuth 2.0. Adds authentication to authorization, enabling clients to verify user identity and obtain basic profile information.

XML-based standard for exchanging authentication and authorization data between identity providers and service providers. Enables enterprise single sign-on.

System for Cross-domain Identity Management (SCIM). Standards-based protocol for automating user provisioning and lifecycle management between identity providers and service providers.

Secure Production Identity Framework for Everyone. Provides cryptographic workload identity for zero-trust architectures via X.509 and JWT SVIDs.

OpenID Shared Signals Framework for real-time security event sharing. Enables continuous access evaluation (CAEP) and risk incident coordination (RISC) between identity providers and relying parties.

OpenID for Verifiable Credential Issuance. Demonstrates credential offers, pre-authorized code token exchange, nonce-bound proof validation, and multi-format VC issuance (mso_mdoc by default, plus dc+sd-jwt, jwt_vc_json, jwt_vc_json-ld, ldp_vc).

OpenID for Verifiable Presentations. Shows DCQL request contracts, request object validation, direct_post/direct_post.jwt responses, and verifier policy decisions.

Coming Soon

WebAuthn
Passwordless public-key credentials, including hardware authenticators
FIDO2
Software and hardware authenticator flows, including roaming devices